Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them.
https://github.com/go-gitea/gitea/security/advisories/GHSA-hcgw-r9gf-8mph
https://github.com/go-gitea/gitea/releases/tag/v28.0.0
https://github.com/go-gitea/gitea/pull/39426
https://github.com/go-gitea/gitea/pull/39010